PDA

View Full Version : Could this be a False Positive???


fredra
March 23rd, 2005, 04:47 PM
Hi
I have this file in the WS_FTP Pro folder and only one AV seem to detect it as "malware". See the below analysis from jotti's site.
My question is
-Could this be a FP?
-What is modification of Win95.Werther.1224???
Only the good doctor has picked this up, hence my question.

Thanks for your response.
Cheers :)

Service load: 0% 100%

File: wsbho2k0.dll
Status: INFECTED/MALWARE
Packers detected: -

AntiVir No viruses found
Avast No viruses found
AVG Antivirus No viruses found
BitDefender No viruses found
ClamAV No viruses found
Dr.Web modification of Win95.Werther.1224
F-Prot Antivirus No viruses found
Fortinet No viruses found
Kaspersky Anti-Virus No viruses found
mks_vir No viruses found
NOD32 No viruses found
Norman Virus Control No viruses found

AndreyKa
March 23rd, 2005, 05:02 PM
You can get an answer by send this file to vms@drweb.com
See details on http://support.drweb.com/sendnew/

tahoma
March 23rd, 2005, 05:29 PM
in my experience it isnt a virus if kav says it isnt. best way to get a quick reply is (also in my opinion) to send it to newvirus@kaspersky.com - usually u get a reply within a couple of hours

fredra
March 23rd, 2005, 07:30 PM
Hi
To AndreyKa and tahoma
Thanks for your input...I took your advuce and sent the file off to both locations as you suggested. If I receive any replies, I will update this thread.
Your help is appreciated.
Cheers :)

Firecat
March 24th, 2005, 01:32 AM
You can contact stormbyte here at Wilders' and ask him the email for sending samples...

fredra
March 24th, 2005, 09:14 PM
To anyone who maybe interessted.
I got a e-mail reply from Kav

"Hello. That is a false positive of Dr.Web antivirus."

So far, no response from Dr. Web, so I will assume that this file is ok, and the good doctor had a hiccup.

Thanks for your feedback.
Cheers :)

Firecat
March 25th, 2005, 07:17 AM
Does KAV test with Dr.Web or have relations with Dr.Web???

Maybe it can be called an FP b'coz it may contain virus code from Win95.Werther but it musta been modified so the file is harmless now. At least thats the way I figure it.